Channel key-based encryption method and apparatus
Abstract
This application relates to communication technologies, and provides a channel key-based encryption method and an apparatus, to resolve a problem that a terminal cannot avoid an attack from a false base station before a security mode is enabled, and a security risk. The method includes: A network device broadcasts a system information block, indicating that channel key generation is supported, where the system information block includes a preamble and a resource configuration of a physical random access channel; receives, on the physical random access channel, a first message from a user equipment, where the first message includes the preamble; sends a second message to the user equipment, where the second message includes configuration information of a first time-frequency resource; receives, on the first time-frequency resource, a third message from the user equipment; and performs channel measurement based on the third message, to obtain a channel key.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A channel key-based encryption method, applied to a network device, wherein the method comprises:
broadcasting a system information block, indicating that channel key generation is supported, wherein the system information block comprises a preamble and a resource configuration of a physical random access channel; receiving, on the physical random access channel, a first message from a user equipment, wherein the first message comprises the preamble; sending a second message to the user equipment, wherein the second message comprises configuration information of a first time-frequency resource; receiving, on the first time-frequency resource, a third message from the user equipment; and performing channel measurement based on the third message, to obtain a channel key, wherein the channel key is for performing data encryption and integrity protection between the network device and the user equipment before a security mode is enabled.
2 . The method according to claim 1 , wherein the method further comprises:
determining, based on the first message, that the user equipment has a channel key generation capability.
3 . The method according to claim 1 , wherein the performing channel measurement based on the third message, to obtain a channel key specifically comprises:
performing channel measurement based on a demodulation reference signal in the second message, to obtain the channel key.
4 . A channel key-based encryption method, applied to a user equipment, wherein the method comprises:
receiving a system information block, wherein the system information block indicates that a network device supports channel key generation, and the system information block comprises a preamble and a resource configuration of a physical random access channel; sending, on the physical random access channel, a first message to the network device, wherein the first message comprises the preamble; receiving a second message from the network device, wherein the second message comprises configuration information of a first time-frequency resource; performing channel measurement based on the second message, to obtain a channel key, wherein the channel key is for performing data encryption and integrity protection between the network device and the user equipment before a security mode is enabled; and sending, on the first time-frequency resource, a third message to the network device.
5 . The method according to claim 4 , wherein the performing channel measurement based on the second message, to obtain a channel key specifically comprises:
performing channel measurement based on a demodulation reference signal in the second message, to obtain the channel key.
6 . A communication apparatus, wherein the communication apparatus comprises a processor and a transmission interface, wherein
the processor is configured to execute instructions stored in a memory, to enable the apparatus to perform: receiving a system information block, wherein the system information block indicates that a network device supports channel key generation, and the system information block comprises a preamble and a resource configuration of a physical random access channel; sending, on the physical random access channel, a first message to the network device, wherein the first message comprises the preamble; receiving a second message from the network device, wherein the second message comprises configuration information of a first time-frequency resource; performing channel measurement based on the second message, to obtain a channel key, wherein the channel key is for performing data encryption and integrity protection between the network device and the user equipment before a security mode is enabled; and sending, on the first time-frequency resource, a third message to the network device.Join the waitlist — get patent alerts
Track US2025016555A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.